The package includes a README, changelog, repository tests, and a stable MIT declaration. Its workflows leave both actions unpinned and the repository has no security policy, so ongoing upkeep needs attention.
61%
Total Score
50
90
50
The package has had no registry release in more than two years and none in the last 12 months. The linked repository was pushed more recently, but registry delivery appears stale.
There were no commits or active maintainers in the measured three-month period. A repository push in February 2026 provides some compensating evidence, but does not establish sustained activity.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though the absence does not indicate that the package is unsafe.
The single analyzed workflow has no unsafe trigger or audit finding, but both of its two action references are unpinned. This is a supply-chain hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.